| <title>Inline script should not run without 'unsafe-inline' script-src directive.</title> |
| <meta http-equiv="Content-Security-Policy" content="script-src 'self';"> |
| <script src='/resources/testharness.js'></script> |
| <script src='/resources/testharnessreport.js'></script> |
| <script src='inlineTests.js'></script> |
| <h1>Inline script should not run without 'unsafe-inline' script-src directive, even for script-src 'self'.</h1> |
| t1.step(function() {assert_unreached('Unsafe inline script ran.');}); |
| <img src='doesnotexist.jpg' onerror='t2.step(function() { assert_unreached("Unsafe inline event handler ran.") });'> |